Balabit - CSR template from the CA administrator
Balabit SCB Solution · Config document · referenced from Certificates and keys
noteDo not copy
rsa_keygen_pubexp:3. A public exponent of 3 was legal but was already discouraged in 2018; 65537, the default of OpenSSL, is the usual choice (general knowledge, not from my documents). <COUNTRY> and <PUT HERE YOUR FQDN> are placeholders, and "Example Org" stands for the organisation.The recipe for a certificate request that the CA administrator of the organisation sent: two OpenSSL commands and the answers to give, as comment lines. The example was made out for another server of the management LAN, dc1-a-vcelk001.adm.example.net, and leaves the common name to the requester.
| Item | Value |
|---|---|
| From | the CA administrator of the organisation's CA |
| Written for | root on the server that requests the certificate |
| Key | RSA 4096, public exponent 3, written unencrypted as a PEM file |
| Configuration | the default openssl.cnf, so no alternative names are requested |
| Subject asked for | country, locality Site 1, organisation Example Org, the server's FQDN, e-mail admin02@example.net; no state, no organisational unit |
| Used for the SCB | not directly: the IPMI requests whose certificates are dated January 2018 give the same answers, with genrsa and 2048-bit keys |
| Source | the end of my working notes, section "CERTIFICATE request - from the CA administrator" |
The commands
The two commands of the template, to run as root on the requesting server.
$ openssl genpkey -algorithm RSA -out dc1-a-vcelk001.adm.example.net.pem -pkeyopt rsa_keygen_bits:4096 -pkeyopt rsa_keygen_pubexp:3 $ openssl req -new -key dc1-a-vcelk001.adm.example.net.pem -out dc1-a-vcelk001.adm.example.net.csr
The answers, as the template gives them.
output 10 lines
# Answers #Country Name (2 letter code) [XX]:<COUNTRY> #State or Province Name (full name) []: #Locality Name (eg, city) [Default City]: Site 1 #Organization Name (eg, company) [Default Company Ltd]: Example Org #Organizational Unit Name (eg, section) []: #Common Name (eg, your name or your server's hostname) []: <PUT HERE YOUR FQDN> #Email Address []: admin02@example.net #A challenge password []: #An optional company name []:
| Line | What it means |
|---|---|
genpkey -algorithm RSA … -pkeyopt rsa_keygen_bits:4096 | the general key command of OpenSSL; genrsa, which my own rounds used, makes the same kind of RSA key (general OpenSSL knowledge) |
-pkeyopt rsa_keygen_pubexp:3 | the public exponent; see the note above |
#State or Province Name (full name) []: | left empty, as the CA's subjects have no state |
#Email Address []: admin02@example.net | the template already carries admin02's address, the same one as in all my requests |
Checked against OpenSSL 3.5
| As built | Today |
|---|---|
-pkeyopt rsa_keygen_pubexp:3 | the default exponent is 65537; OpenSSL documents 3 as accepted "for legacy reasons" and deprecated |
genpkey -algorithm RSA … rsa_keygen_bits:4096 | unchanged |
Dropping the rsa_keygen_pubexp option is all the template needs.